CrowdStrike Unified Alerts Add-on for Splunk Installation and Configuration Guide v2.3.0+

This guide covers the deployment, configuration and usage of the CrowdStrike Unified Alerts Technical Add-on (TA) for Splunk v2.3.0 and above. The CrowdStrike Unified Alerts Technical Add-on for Splunk allows CrowdStrike customers to retrieve Alert event data from multiple CrowdStrike produces via API and index it into Splunk.

For deploying and configuring the CrowdStrike Unified Alerts Splunk Technical Add-On located on Splunkbase.

Tech Hub

  • OS icon
  • deployment icon
  • installation icon

For technical information on installation, policy configuration and more, please visit the CrowdStrike Tech Hub.

Visit Tech Hub